AI Governance

Uber Fined €825M Under GDPR for Letting Algorithms Fire Drivers

The Dutch DPA fined Uber €825M for using automated systems to suspend drivers with no meaningful human review, the second-largest GDPR penalty ever issued.

LUMIEN5 min read
Uber Fined €825M Under GDPR for Letting Algorithms Fire Drivers

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) announced an €825 million fine against Uber on Monday, making it the second-largest penalty ever issued under the GDPR, behind only the €1.2 billion fine against Meta in 2023. The regulator found that Uber used a fully automated system to suspend and permanently deactivate drivers across the EU, cutting off their income with no meaningful human review and little explanation, in direct violation of Article 22 of the GDPR.

What happened

Detail Fact
Fine amount €825 million (approx. $1 billion)
Issuing authority Dutch Data Protection Authority (Autoriteit Persoonsgegevens)
GDPR ranking Second-largest fine ever, behind Meta’s €1.2 billion (2023)
Uber’s previous fine, same authority €290 million in 2024 for improper data transfers to the US
Core legal violation Article 22 GDPR: automated decisions with significant effects, no valid legal basis
Additional failures Inadequate transparency; no right to human review before suspension

Uber’s automated system monitored drivers using signals including fraud detection flags, customer complaints, trip cancellations, and account verification checks. When the system detected a potential violation, it could immediately block a driver’s access to the platform, removing their income without any human decision first.

Drivers typically received a generic in-app message citing a community guidelines violation, with no specific explanation of what triggered the action. The investigation, started after complaints from drivers and advocacy groups, found that in a significant number of cases no human intervened before the account was disabled.

Uber argued that human staff were available to handle appeals. The Authority rejected that argument: the initial, consequential decision was made by the algorithm alone, and post-hoc appeal is not the same as meaningful pre-decision human oversight.

Why Article 22 of the GDPR is the key issue

Article 22 gives individuals the right not to be subject to a decision made solely by automated processing, including profiling, when that decision produces “legal or similarly significant effects.” The Authority ruled that losing access to the Uber platform clearly meets that standard because it directly affects a driver’s ability to earn a living.

Under Article 22, automated decisions of this kind are prohibited unless the company can point to explicit consent, contractual necessity, or EU law authorization, and even then must put proper safeguards in place. Regulators found Uber failed on three counts:

  1. No valid legal basis for carrying out solely automated decisions with significant effects.
  2. Inadequate transparency: drivers were not told they were subject to automated decision-making, how the logic worked, or which factors caused their suspension.
  3. No sufficient safeguards: drivers had no guaranteed right to human review, no opportunity to state their case, and no mechanism to contest the decision before it took effect.

What Uber says and what happens next

Uber has stated it will appeal the ruling to the District Court in the Netherlands. The company maintains that its processes comply with European law and that human reviewers are involved in its safety and fraud systems. It also argues that automated tools are necessary to manage platform safety at scale.

An appeal could suspend the fine during proceedings, a process that could run for years. Regardless of appeal outcome, Uber has been ordered to reform its deactivation processes: ensuring real human review before any suspension with significant effects, and giving drivers clearer explanations. Failure to comply will trigger additional periodic penalty payments on top of the €825 million.

Why does this matter beyond Uber?

Ride-hailing, delivery, and freelance platforms across Europe use algorithmic management in almost exactly the same way: algorithms assign work, set pay, evaluate performance, and discipline or remove workers. This ruling treats that practice as a high-risk privacy and labor issue, not just a business efficiency choice.

The message from Dutch regulators is direct: you cannot automate terminations in the EU. Any system that makes a significant decision about a worker must include a human with real authority to reverse the machine’s verdict, and the worker must understand how that decision was reached. This applies whether the platform calls those workers employees, contractors, or partners.

The fine lands as the EU accelerates enforcement of both the GDPR and the EU AI Act, which classifies certain AI systems used in employment and worker management as high risk, requiring additional obligations around transparency and human oversight. For any business using AI to manage people or automate consequential decisions, the compliance gap is now measured in nine figures. Our AI integration work for clients always factors in these human-oversight requirements, and this ruling underlines why that is not optional.

For context on how automated decision-making concerns are shaping AI policy more broadly, see our coverage of OpenAI’s push to strengthen California’s AI safety law.

Our take

This ruling matters far beyond the gig economy. Any business that uses an AI or rules-based system to make decisions that affect customers, workers, or contractors needs to look hard at whether a human is genuinely in the loop before the decision is executed, not just available for appeal afterward. The Dutch Authority’s distinction between “human reviewers exist” and “meaningful human review happens first” is sharp, and it will be used again.

The €825 million figure will get the headlines, but the operational requirement to reform the deactivation process is the harder long-term problem for Uber. Building a compliant workflow at platform scale while maintaining fraud prevention is a genuine engineering and policy challenge, not a quick fix.

If your business uses automated scoring, flagging, or account actions of any kind, now is the time to map every decision that could significantly affect a user and confirm a human has real authority to intervene before it fires. That audit is cheaper than the alternative.

What to do about it

  1. List every automated decision your systems make that could significantly affect a customer, user, or worker (account suspension, score changes, access restrictions).
  2. Confirm each decision has a documented legal basis under GDPR Article 22 (consent, contractual necessity, or EU law).
  3. Build a pre-decision human review step into any high-stakes automated action, not just a post-hoc appeal path.
  4. Update your privacy notices and in-app messaging so affected parties understand the logic behind any automated decision and know how to challenge it.
  5. If you are using third-party AI tools to manage people or accounts, ask your vendor to document their Article 22 compliance posture in writing.

Source: Bing News · Meta AI

Frequently asked questions

Why was Uber fined €825 million under the GDPR?

The Dutch Data Protection Authority found that Uber used a fully automated system to suspend and permanently deactivate drivers with no meaningful human review before the decision took effect, violating Article 22 of the GDPR, which prohibits automated decisions that significantly affect individuals without proper safeguards and transparency.

What is GDPR Article 22 and why does it matter here?

Article 22 gives people the right not to be subject to a decision made solely by automated processing when that decision has legal or similarly significant effects on them. Regulators ruled that losing access to a platform that is someone's income source clearly meets that threshold, requiring a valid legal basis, transparency, and the right to human review before the decision takes effect.

Is this the largest GDPR fine ever?

No. Uber's €825 million fine is the second-largest ever issued under the GDPR. The largest was the €1.2 billion fine against Meta in 2023 for transferring EU user data to the United States.

Will Uber pay the €825 million fine?

Uber has stated it will appeal the decision to the District Court in the Netherlands, a process that could take years. An appeal may suspend payment during proceedings, but Uber has also been ordered to reform its deactivation systems regardless of the fine's outcome.

More from AI